Cloud Security Vendor Evaluation Checklist Form
Use this form to evaluate a cloud security vendor’s security controls, readiness, and overall fit for your organization.
Vendor Overview
Vendor Name
*
Vendor Website or Product URL
*
Evaluator Name or Team
*
Evaluation Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Cloud Security Checklist
Identity and access management
*
Rows
Meets
Partially meets
Does not meet
Not assessed
Multi-factor authentication
1
2
3
4
Least-privilege access controls
5
6
7
8
Role-based access management
9
10
11
12
Privileged access review
13
14
15
16
Encryption and data protection
*
Rows
Meets
Partially meets
Does not meet
Not assessed
Data encrypted at rest
17
18
19
20
Data encrypted in transit
21
22
23
24
Customer-managed key support
25
26
27
28
Data retention and deletion controls
29
30
31
32
Logging, monitoring, and vulnerability management
*
Rows
Meets
Partially meets
Does not meet
Not assessed
Centralized audit logging
33
34
35
36
Security monitoring and alerting
37
38
39
40
Vulnerability scanning
41
42
43
44
Patch and remediation SLAs
45
46
47
48
Incident response, compliance, and security architecture
*
Rows
Meets
Partially meets
Does not meet
Not assessed
Documented incident response process
49
50
51
52
Compliance certifications available
53
54
55
56
Shared responsibility model documented
57
58
59
60
Secure deployment architecture reviewed
61
62
63
64
Evaluation Outcome
Overall Recommendation
*
Approve
Approve with Conditions
Needs More Information
Reject
Priority Concerns / Gaps
Identity and Access Controls
Data Protection
Network Security
Incident Response
Compliance Alignment
Logging and Monitoring
Vendor Transparency
Other
Additional Comments / Next Steps
Submit
Should be Empty: